Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

FB vir, restartování NTB

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

FB vir, restartování NTB

#1 Příspěvek od LukassM »

Zdravím, bratránkovi se podařilo pokecat si s angličtinou, naklepnout odkaz na "youtube" a stáhnout aktualizaci.
Přesný průběh událostí z doby než se sesypal NTB z něj asi nedostanu (ale asi dva dny ještě fungoval), každopádně teď se pořád dokola restartuje po necelé minutě. Zrestartuje se jak z normálního tak i nouzového režimu s přístupem na net.

Když je NTB bez přístupu k internetu, nerestartuje se.
(mezi restarty jsem wifi vypnout nestíhal takže jsem vypnul modem a pak teprve jsem stihl vypnout automatické připojování k síti)

Systém: Vista, SP2


Chtěl bych na ntb přenést najednou všechny programy které pravděpodobně využijeme, abych nemusel pendlovat s flashkou a náhodou si tak nepřenesl vir na další pc...

Tedy stáhnu a hodím na zavirované NTB tyto čtyři: RSIT abych sem dal log a na likvidaci ComboFix, dál jsem viděl v jiných vláknech RogueKiller s Malwarebytes; a dál se nechám vést, správně?
Děkuji za pomoc ;)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, restartování NTB

#2 Příspěvek od vyosek »

Zdravim a pekny den preji :)

:arrow: Zatim tam dejte RSIT a uvidime co dale - dle logu pak dame dalsi soft
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

Re: FB vir, restartování NTB

#3 Příspěvek od LukassM »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Milan at 2011-08-22 19:36:43
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 6 GB (10%) free of 57 GB
Total RAM: 1919 MB (53% free)

HijackThis download failed

=========Mozilla firefox=========

ProfilePath - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/skinit/icq/"
prefs.js - "extensions.enabledItems" - "ar@dictionaries.addons.mozilla.org:2.0.20080110, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.8, cs@dictionaries.addons.mozilla.org:1.0.1, {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.20"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5]
"Description"=Office Live Update v1.5
"Path"=C:\Program Files\Microsoft\Office Live\npOLW.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
talkback@mozilla.org
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsILegitCheckPlugin.xpt
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
npLegitCheckPlugin.dll
npnul32.dll
NPOFFICE.DLL
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\
ar@dictionaries.addons.mozilla.org
cs@dictionaries.addons.mozilla.org
staged-xpis
{20a82645-c095-46ed-80e3-08825760534b}
{800b5000-a755-47e1-992b-48a1c1357f07}
{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
{EEE6C361-6118-11DC-9C72-001320C79847}

C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\
icqplugin-1.xml
icqplugin-10.xml
icqplugin-11.xml
icqplugin-12.xml
icqplugin-13.xml
icqplugin-14.xml
icqplugin-15.xml
icqplugin-16.xml
icqplugin-17.xml
icqplugin-18.xml
icqplugin-19.xml
icqplugin-2.xml
icqplugin-20.xml
icqplugin-21.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
live-search.xml
sweetim.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-11-07 1088296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}]
Ask Search Assistant BHO

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-07-11 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-02-15 4390912]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-11-22 815104]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice []
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"wxpdrv"=C:\Windows\services32.exe [2011-08-21 1213440]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-15-0\svchost.exe [2011-08-21 1213440]
"tray_ico1"=C:\Windows\update.tray-2-0\svchost.exe [2011-08-21 1213440]
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"3693579.exe"=C:\Windows\Temp\3693579.exe [2011-08-22 258048]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-08-22 258048]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-08-22 258048]
"6416839.exe"=C:\Users\Milan\AppData\Local\Temp\6416839.exe [2011-08-22 258048]
"6835511.exe"=C:\Users\Milan\AppData\Local\Temp\6835511.exe [2011-08-22 258048]
"4515126.exe"=C:\Windows\Temp\4515126.exe [2011-08-22 258048]
"systemup"=C:\Windows\systemup.exe [2011-08-22 137728]
"6851489.exe"=C:\Users\Milan\AppData\Local\Temp\6851489.exe [2011-08-22 258048]
"9182489.exe"=C:\Users\Milan\AppData\Local\Temp\9182489.exe [2011-08-22 258048]
"824970.exe"=C:\Windows\Temp\824970.exe [2011-08-22 634880]
"4191654.exe"=C:\Windows\Temp\4191654.exe [2011-08-22 258048]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-08-22 232960]
"5336910-loader2.exe"=C:\Windows\Temp\5336910-loader2.exe [2011-08-22 258048]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
""= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-11-07 21633320]
"T-Mobile Communication Centre"=C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe [2007-10-25 956296]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
"EPSON Stylus DX4400 Series"=C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE [2007-03-01 180736]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2010-08-20 33120]
"ICQ"=C:\Program Files\ICQ7.5\ICQ.exe [2011-08-01 124480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
C:\Program Files\Cyberlink\Shared Files\brs.exe [2007-11-16 91432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Nero\Nero 7\InCD\InCD.exe [2007-03-12 1055792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-10-11 62760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-10-28 72736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
C:\Windows\sm56hlpr.exe [2005-05-26 544768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"msacm.divxa32"=msaud32_divx.acm
"msacm.siren"=sirenacm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-08-22 19:36:44 ----D---- C:\Program Files\trend micro
2011-08-22 19:36:43 ----D---- C:\rsit
2011-08-22 18:18:33 ----A---- C:\Windows\l1rezerv.exe
2011-08-22 18:01:54 ----A---- C:\Windows\iecheck_iplist.txt
2011-08-22 17:56:34 ----HD---- C:\Windows\update.7.1
2011-08-22 17:56:23 ----HD---- C:\Windows\update.2
2011-08-22 17:13:36 ----D---- C:\Windows\ufa
2011-08-22 17:13:36 ----D---- C:\Windows\rpcminer
2011-08-22 17:13:36 ----D---- C:\Windows\phoenix
2011-08-22 17:13:35 ----A---- C:\Windows\unrar.exe
2011-08-22 17:03:23 ----A---- C:\Windows\btc_client_iplist.txt
2011-08-22 16:49:16 ----HD---- C:\Windows\update.5.0
2011-08-22 16:49:00 ----A---- C:\Windows\systemup.exe
2011-08-22 16:43:59 ----A---- C:\Windows\iplist.txt
2011-08-22 16:43:27 ----A---- C:\Windows\sysdriver32_.exe
2011-08-22 16:43:09 ----A---- C:\Windows\sysdriver32.exe
2011-08-22 16:42:55 ----A---- C:\Windows\front_ip_list.txt
2011-08-21 20:26:27 ----D---- C:\Windows\av_ico
2011-08-21 20:24:34 ----HD---- C:\Windows\update.1
2011-08-21 20:24:28 ----HD---- C:\Windows\update.tray-2-0-lnk
2011-08-21 20:24:28 ----HD---- C:\Windows\update.tray-2-0
2011-08-21 20:24:28 ----HD---- C:\Windows\update.tray-15-0-lnk
2011-08-21 20:24:28 ----HD---- C:\Windows\update.tray-15-0
2011-08-21 20:11:38 ----A---- C:\Windows\winlog-ids.txt
2011-08-21 20:11:38 ----A---- C:\Windows\winlog-dirs.txt
2011-08-21 20:11:28 ----A---- C:\Windows\services32.exe
2011-08-19 14:28:32 ----A---- C:\Windows\system32\ezGOSvcApp.exe
2011-08-19 14:28:32 ----A---- C:\Windows\system32\ezGOSvc.dll
2011-08-19 14:09:54 ----SHD---- C:\Config.Msi
2011-08-15 16:00:39 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-15 16:00:37 ----A---- C:\Windows\system32\iertutil.dll
2011-08-15 16:00:36 ----A---- C:\Windows\system32\jscript.dll
2011-08-15 16:00:36 ----A---- C:\Windows\system32\ieui.dll
2011-08-15 16:00:35 ----A---- C:\Windows\system32\jscript9.dll
2011-08-15 16:00:34 ----A---- C:\Windows\system32\wininet.dll
2011-08-15 16:00:34 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-15 16:00:32 ----A---- C:\Windows\system32\urlmon.dll
2011-08-15 16:00:32 ----A---- C:\Windows\system32\url.dll
2011-08-15 16:00:32 ----A---- C:\Windows\system32\ieframe.dll
2011-08-15 16:00:28 ----A---- C:\Windows\system32\mshtml.dll
2011-08-10 16:32:00 ----A---- C:\Windows\system32\winsrv.dll
2011-08-10 16:31:57 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-10 16:31:53 ----A---- C:\Windows\system32\xmllite.dll
2011-08-10 16:31:28 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-08-10 16:31:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-10 16:31:22 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-07-27 19:18:10 ----D---- C:\Program Files\PC Suite For Android Handset

======List of files/folders modified in the last 1 month======

2011-08-22 19:36:45 ----D---- C:\Windows\Prefetch
2011-08-22 19:36:45 ----D---- C:\Windows\inf
2011-08-22 19:36:44 ----RD---- C:\Program Files
2011-08-22 19:36:44 ----D---- C:\Windows\Temp
2011-08-22 19:33:11 ----D---- C:\ProgramData\Easybits GO
2011-08-22 19:18:29 ----D---- C:\Windows\system32\drivers\etc
2011-08-22 19:18:26 ----D---- C:\Windows\system32\catroot2
2011-08-22 19:18:22 ----SHD---- C:\System Volume Information
2011-08-22 19:09:22 ----D---- C:\Windows
2011-08-22 19:07:45 ----A---- C:\Windows\NeroDigital.ini
2011-08-22 18:53:03 ----D---- C:\Users\Milan\AppData\Roaming\Skype
2011-08-22 18:42:11 ----D---- C:\Windows\system32\drivers
2011-08-22 18:23:42 ----A---- C:\Windows\system32\acovcnt.exe
2011-08-22 18:10:48 ----A---- C:\Windows\ntbtlog.txt
2011-08-22 17:43:49 ----HD---- C:\ProgramData
2011-08-22 17:43:48 ----HD---- C:\Windows\system32\GroupPolicy
2011-08-22 17:27:10 ----D---- C:\Users\Milan\AppData\Roaming\go
2011-08-21 20:28:47 ----D---- C:\Program Files\Mozilla Firefox
2011-08-19 16:04:00 ----RSD---- C:\Windows\assembly
2011-08-19 16:04:00 ----D---- C:\Windows\Microsoft.NET
2011-08-19 14:28:32 ----D---- C:\Windows\System32
2011-08-19 14:27:10 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-19 14:22:07 ----SHD---- C:\Windows\Installer
2011-08-19 14:11:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-15 16:44:36 ----D---- C:\Windows\winsxs
2011-08-15 16:24:20 ----D---- C:\Windows\system32\catroot
2011-08-15 16:19:42 ----D---- C:\Windows\system32\migration
2011-08-15 16:19:41 ----D---- C:\Program Files\Internet Explorer
2011-08-15 16:00:01 ----D---- C:\Program Files\Windows Mail
2011-08-13 17:33:29 ----A---- C:\Windows\system32\mrt.exe
2011-08-13 17:18:40 ----A---- C:\Windows\win.ini
2011-08-03 00:03:52 ----D---- C:\Users\Milan\AppData\Roaming\ICQ
2011-08-03 00:03:34 ----D---- C:\Program Files\NemExpress
2011-08-02 22:58:33 ----D---- C:\Program Files\NEM3000
2011-08-02 22:57:40 ----A---- C:\Windows\PhotoSnapViewer.INI
2011-08-02 22:09:37 ----D---- C:\Program Files\ICQ7.5
2011-07-30 16:14:38 ----D---- C:\Program Files\Microsoft Office
2011-07-27 16:49:41 ----D---- C:\Windows\system32\WDI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-05-17 436792]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdir;epfwtdir; C:\Windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
R1 InCDPass;InCDPass; C:\Windows\system32\drivers\InCDPass.sys [2007-03-12 37040]
R1 incdrm;InCD Reader; C:\Windows\system32\drivers\InCDRm.sys [2007-03-12 38576]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2005-08-02 64896]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B}; \??\C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 41456]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2006-11-14 43520]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-01-13 954368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-02-14 1740904]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-02-02 2385920]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-06 51200]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2005-05-26 839724]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2006-11-22 181304]
R3 WCPU;WCPU; \??\C:\Program Files\P4G\WCPU.sys [2007-01-03 11120]
R4 InCDfs;InCD File System; C:\Windows\system32\drivers\InCDFs.sys [2007-03-12 118064]
S2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2006-11-16 15216]
S3 a8gm0w87;a8gm0w87; C:\Windows\system32\drivers\a8gm0w87.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2006-11-02 19456]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2006-11-02 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2006-11-02 220160]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2006-11-02 29184]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 KMWDFILTER;HIDUASDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2008-10-09 17408]
S3 lvupdtio;lvupdtio; \??\C:\Program Files\ASUS\ASUS Live Update\SYS64\lvupdtio.sys [2006-11-09 15216]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945BG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2006-10-14 4422560]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2006-11-02 49664]
S3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2006-11-02 41064]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-11 15872]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WINUSB;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUSB.SYS [2009-04-11 31616]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-02-06 94208]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2007-02-02 565248]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 ezGOSvc;Easybits GO Services for Windows; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 InCDsrv;InCD Helper; C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe [2007-03-12 931376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 lxbk_device;lxbk_device; C:\Windows\system32\lxbkcoms.exe [2008-02-19 537256]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-08-06 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2010-08-06 103736]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-10-15 243056]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2006-12-29 123248]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-08-22 355840]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-08-22 634880]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-08-22 258048]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2006-11-01 77824]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-08-21 1213440]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, restartování NTB

#4 Příspěvek od vyosek »

:arrow: Ten NOD32 je legalni = zakoupena licence :???:

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost 2 a potvrte enterem
  • Utilita provede svou cinnost a da log - ten sem vlozte
  • Nyni znovu, ale zvolte moznost 3 a pote jeste 4 - logy opet vlozte
:arrow: Stahnete OTL (viz muj podpis) a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    adp3132.sys
    AGP440.sys
    ahcix86.sys
    ahcix86s.sys
    atapi.sys
    autochk.exe
    cdrom.sys
    cngaudit.dll
    cryptsvc.dll
    eNetHook.dll
    eventlog.dll
    explorer.exe
    hal.dll
    Changer.sys
    iaStor.sys
    iastorv.sys
    IdeChnDr.sys
    isapnp.sys
    JakNDis.sys
    KR10N.sys
    logevent.dll
    lsass.exe
    mv61xx.sys
    ndis.sys
    netlogon.dll
    ntelogon.dll
    nvata.sys
    nvatabus.sys
    nvgts.sys
    nvraid.sys
    nvrd32.sys
    nvstor.sys
    nvstor32.sys
    scecli.dll
    sceclt.dll
    smss.exe
    svchost.exe
    symmpi.sys
    tcpip.sys
    userinit.exe
    vaxscsi.sys
    viamraid.sys
    viasraid.sys
    ViPrt.sys
    winlogon.exe
    ws2_32.dll
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    type c:\boot.ini >> test.txt /c
    %SystemDrive%\PhysicalMBR.bin /md5 
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

Re: FB vir, restartování NTB

#5 Příspěvek od LukassM »

ten NOD bude podle mne nejspíš cracknutej (jestli nebyla na NTB doživotní licence zdarma :D)
jestli neni náhodou ofiko můžu zkusit zjistit

a jedeme logy
RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Milan [Admin rights]
Mode: Remove -- Date : 08/22/2011 20:03:53

Bad processes: 0

Registry Entries: 28
[SUSP PATH] HKLM\[...]\Run : wxpdrv (C:\Windows\services32.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico0 (C:\Windows\update.tray-15-0\svchost.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico1 (C:\Windows\update.tray-2-0\svchost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3693579.exe ("C:\Windows\Temp\3693579.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\Windows\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\Windows\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 6416839.exe ("C:\Users\Milan\AppData\Local\Temp\6416839.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 6835511.exe ("C:\Users\Milan\AppData\Local\Temp\6835511.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4515126.exe ("C:\Windows\Temp\4515126.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : systemup ("C:\Windows\systemup.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 6851489.exe ("C:\Users\Milan\AppData\Local\Temp\6851489.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9182489.exe ("C:\Users\Milan\AppData\Local\Temp\9182489.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 824970.exe ("C:\Windows\Temp\824970.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4191654.exe ("C:\Windows\Temp\4191654.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("C:\Windows\l1rezerv.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 5336910-loader2.exe ("C:\Windows\Temp\5336910-loader2.exe") -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\Windows\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\Windows\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\Windows\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\Windows\update.1\svchost.exe srv) -> DELETED
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)
[HJ] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)

Particular Files / Folders:

HOSTS File:
127.0.0.1 localhost
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
127.0.0.1 fr-fr.facebook.com
127.0.0.1 fy-nl.facebook.com
[...]


Finished : << RKreport[1].txt >>
RKreport[1].txt


RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Milan [Admin rights]
Mode: HOSTSFix -- Date : 08/22/2011 20:04:41

Bad processes: 0

HOSTS File:
127.0.0.1 localhost
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
127.0.0.1 fr-fr.facebook.com
127.0.0.1 fy-nl.facebook.com
[...]


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt


RogueKiller V5.3.3 [08/18/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Milan [Admin rights]
Mode: ProxyFix -- Date : 08/22/2011 20:05:37

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, restartování NTB

#6 Příspěvek od vyosek »

Nedavejte logy do citace
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

Re: FB vir, restartování NTB

#7 Příspěvek od LukassM »

OTL logfile created on: 22.8.2011 20:08:56 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Milan\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,87 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 53,91% Memory free
3,99 Gb Paging File | 2,95 Gb Available in Paging File | 74,01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55,89 Gb Total Space | 5,72 Gb Free Space | 10,23% Space Free | Partition Type: NTFS
Drive D: | 49,06 Gb Total Space | 12,89 Gb Free Space | 26,28% Space Free | Partition Type: NTFS
Drive F: | 243,73 Mb Total Space | 182,91 Mb Free Space | 75,05% Space Free | Partition Type: FAT

Computer Name: MILANPC-PRACE | User Name: Milan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2011.08.22 19:56:36 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Milan\Desktop\OTL.exe
PRC - [2011.08.01 10:28:16 | 000,124,480 | ---- | M] (ICQ, LLC.) -- C:\Program Files\ICQ7.5\ICQ.exe
PRC - [2011.02.25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2009.12.23 23:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2009.04.11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008.02.19 09:12:18 | 000,537,256 | ---- | M] ( ) -- C:\Windows\System32\lxbkcoms.exe
PRC - [2008.01.19 09:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007.10.25 19:16:58 | 000,956,296 | ---- | M] (Gemfor s.r.o.) -- C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe
PRC - [2007.03.12 18:54:10 | 000,931,376 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
PRC - [2007.02.15 11:07:15 | 004,390,912 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007.02.10 01:40:34 | 000,225,280 | ---- | M] (ATK0100) -- C:\Program Files\ATK Hotkey\HControl.exe
PRC - [2007.02.09 19:38:36 | 000,049,520 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
PRC - [2007.02.06 03:13:14 | 000,094,208 | ---- | M] () -- C:\Program Files\ATK Hotkey\ASLDRSrv.exe
PRC - [2007.01.18 23:48:42 | 002,752,512 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2007.01.18 05:41:34 | 000,843,776 | ---- | M] (ATK) -- C:\Program Files\ASUS\Splendid\ACMON.exe
PRC - [2007.01.18 04:26:36 | 007,708,672 | ---- | M] () -- C:\Program Files\ATKOSD2\ATKOSD2.exe
PRC - [2007.01.18 02:34:22 | 000,135,168 | ---- | M] (ATK) -- C:\Program Files\P4G\BatteryLife.exe
PRC - [2007.01.13 07:41:40 | 000,278,528 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2006.12.29 01:17:50 | 000,123,248 | ---- | M] () -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
PRC - [2006.12.21 08:03:38 | 001,036,288 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe
PRC - [2006.12.19 02:26:26 | 002,420,736 | ---- | M] () -- C:\Program Files\ATK Hotkey\ATKOSD.exe
PRC - [2006.12.07 19:51:04 | 001,143,152 | ---- | M] (ASUS) -- C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
PRC - [2006.11.01 07:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2006.10.28 05:13:48 | 000,270,336 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2006.01.24 08:14:10 | 000,069,632 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
PRC - [2005.07.07 00:43:42 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\Windows\System32\ACEngSvr.exe


========== Modules (No Company Name) ==========

MOD - [2011.08.19 15:50:36 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\4117485024b0f652b9fbb66ff5025896\System.Management.ni.dll
MOD - [2011.08.19 15:47:38 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a6d889aa69fd51c100352f23c7cebd22\System.Runtime.Remoting.ni.dll
MOD - [2011.08.19 15:47:18 | 011,804,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5aa9131000876de66160ff713b543d99\System.Web.ni.dll
MOD - [2011.08.19 15:46:27 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\c50d9d540acecdef29c31201e203a331\System.Windows.Forms.ni.dll
MOD - [2011.08.19 15:46:05 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\d8d83838f9840bde901df516ba3de588\System.Drawing.ni.dll
MOD - [2011.08.19 15:45:54 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\4c3cda96b8f12220da20f2f8d1b9439c\System.Xml.ni.dll
MOD - [2011.08.19 15:45:43 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\29c6ef7f07d89496c72a1bbf718aed5d\System.Configuration.ni.dll
MOD - [2011.08.19 14:21:24 | 007,950,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b9ea0d414c4861120bfb7365d8ec0939\System.ni.dll
MOD - [2011.08.19 14:21:06 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f6deb187f24bb3185841092b89fbfdbb\mscorlib.ni.dll
MOD - [2010.02.10 18:10:12 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009.03.31 20:04:50 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_cs_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009.03.31 20:04:50 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_cs_b77a5c561934e089\mscorlib.resources.dll
MOD - [2007.10.01 04:40:37 | 001,671,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2589.34579__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2007.10.01 04:40:37 | 000,225,280 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2589.34534__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2007.10.01 04:40:37 | 000,184,320 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2589.34592__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2007.10.01 04:40:37 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2589.34808__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2007.10.01 04:40:37 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2589.34570__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2007.10.01 04:40:37 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2589.34591__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.dll
MOD - [2007.10.01 04:40:37 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2589.34555__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2007.10.01 04:40:37 | 000,015,360 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2589.34693__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2007.10.01 04:40:36 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2589.34761__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2007.10.01 04:40:34 | 000,483,328 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2589.34851__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2007.10.01 04:39:37 | 000,073,728 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2589.34549__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:36 | 000,344,064 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2589.34776__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:36 | 000,139,264 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.2589.34843__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:36 | 000,135,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2589.34857__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:36 | 000,090,112 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2589.34781__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2007.10.01 04:39:36 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2589.34773__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:36 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2589.34842__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:35 | 000,667,648 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2589.34707__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:35 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2589.34795__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2007.10.01 04:39:34 | 000,573,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2589.34606__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:34 | 000,438,272 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2589.34557__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:34 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2589.34748__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:34 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2589.34613__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2007.10.01 04:39:34 | 000,208,896 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2589.34599__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:34 | 000,118,784 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2589.34728__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:34 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2589.34703__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:34 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2589.34727__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:34 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2589.34612__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:34 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2589.34747__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:33 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2589.34698__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2007.10.01 04:39:33 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2589.34694__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:33 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2589.34702__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2007.10.01 04:39:33 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2560.26010__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2007.10.01 04:39:33 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2560.26010__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2007.10.01 04:39:33 | 000,006,656 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2007.10.01 04:39:32 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2560.25961__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2007.10.01 04:39:32 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2560.25971__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2007.10.01 04:39:32 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2537.29860__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2007.10.01 04:39:32 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2560.26012__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2007.10.01 04:39:32 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2560.25959__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2007.10.01 04:39:32 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2560.26040__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2007.10.01 04:39:32 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2560.25964__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2007.10.01 04:39:32 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2560.25982__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2007.10.01 04:39:32 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2560.25973__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2007.10.01 04:39:32 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2560.25968__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2007.10.01 04:39:32 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2560.25974__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2007.10.01 04:39:32 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2560.26001__90ba9c70f846762e\DEM.OS.I0602.dll
MOD - [2007.10.01 04:39:32 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2560.26002__90ba9c70f846762e\DEM.OS.dll
MOD - [2007.10.01 04:39:32 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2560.25997__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2007.10.01 04:39:32 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2531.19989__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2007.10.01 04:39:32 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2560.25988__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2007.10.01 04:39:32 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2560.25987__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2560.26001__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shared\2.0.2560.25988__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2560.25998__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2560.26000__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2560.25998__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2560.26000__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2560.25999__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2560.25988__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,028,672 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2560.25987__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2560.26012__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2560.25999__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2560.25986__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2560.25982__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2007.10.01 04:39:31 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2560.25987__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2007.10.01 04:39:30 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2560.26001__90ba9c70f846762e\APM.Foundation.dll
MOD - [2007.10.01 04:39:30 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2560.25960__90ba9c70f846762e\AEM.Foundation.dll
MOD - [2007.10.01 04:39:30 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2531.19989__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll
MOD - [2007.10.01 04:39:30 | 000,016,384 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2560.25970__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2007.10.01 04:39:16 | 000,110,592 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray.resources\2.0.2589.34827_cs_90ba9c70f846762e\CLI.Component.Systemtray.resources.dll
MOD - [2007.10.01 04:39:16 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.2589.34878__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2007.10.01 04:39:15 | 001,404,928 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2589.34543__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2007.10.01 04:39:15 | 000,466,944 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2589.34565__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2007.10.01 04:39:15 | 000,389,120 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2589.34827__90ba9c70f846762e\CLI.Component.Systemtray.dll
MOD - [2007.10.01 04:39:15 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2589.34834__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2007.10.01 04:39:15 | 000,090,112 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2589.34533__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2007.10.01 04:39:15 | 000,057,344 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2589.34833__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2007.10.01 04:39:15 | 000,053,248 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.2589.34533__90ba9c70f846762e\ATIDEMOS.dll
MOD - [2007.10.01 04:39:15 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2560.25970__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2007.10.01 04:39:15 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2560.25980__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2007.10.01 04:39:15 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2560.25964__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2007.10.01 04:39:15 | 000,024,576 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2560.26010__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2007.10.01 04:39:15 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2560.25982__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2007.10.01 04:39:15 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2560.25966__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2007.10.01 04:39:15 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2560.25981__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2007.10.01 04:39:15 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2560.26004__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2007.10.01 04:39:15 | 000,019,968 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.2589.34834__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2007.10.01 04:39:14 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2589.34532__90ba9c70f846762e\AEM.Server.dll
MOD - [2007.10.01 04:39:14 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2007.02.09 19:38:36 | 000,049,520 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe
MOD - [2007.02.02 09:01:29 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2007.01.10 23:22:38 | 000,016,384 | R--- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2006.12.20 04:16:04 | 000,073,728 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
MOD - [2006.12.09 22:47:40 | 000,208,896 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswui.dll
MOD - [2006.12.09 18:34:36 | 000,139,264 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipsw_cfgmgr.dll
MOD - [2006.12.07 19:42:48 | 000,188,416 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswsysmon.dll
MOD - [2006.12.07 19:41:10 | 000,053,248 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswresmgr.dll
MOD - [2006.12.07 19:41:02 | 000,204,800 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswcore.dll
MOD - [2006.12.07 18:29:06 | 000,007,168 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\iphelper.dll
MOD - [2006.12.07 01:55:32 | 000,053,248 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswhlp.dll
MOD - [2006.12.07 01:55:22 | 000,086,016 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswds.dll
MOD - [2006.12.07 01:42:26 | 000,094,208 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\cxcmrt.dll
MOD - [2006.11.21 23:15:32 | 000,073,728 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswgblset.dll
MOD - [2006.11.21 23:15:20 | 000,086,016 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ipswobj.dll
MOD - [2006.11.17 19:17:46 | 000,049,152 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\LogonStartup.dll
MOD - [2006.09.22 22:50:40 | 000,049,152 | ---- | M] () -- C:\Program Files\ASUS\Net4Switch\ResItf.dll
MOD - [2005.07.23 06:30:20 | 000,065,536 | ---- | M] () -- C:\Windows\System32\TosCommAPI.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Unknown | Stopped] -- -- (wxpdrivers)
SRV - File not found [Unknown | Stopped] -- -- (srvsysdriver32)
SRV - File not found [Unknown | Stopped] -- -- (srviecheck)
SRV - File not found [Unknown | Stopped] -- -- (srvbtcclient)
SRV - File not found [Auto | Stopped] -- -- (ekrn)
SRV - File not found [On_Demand | Stopped] -- -- (EhttpSrv)
SRV - File not found [Auto | Stopped] -- -- (CLTNetCnService)
SRV - [2011.05.29 12:01:37 | 000,073,600 | ---- | M] () [Auto | Running] -- C:\Windows\System32\ezGOSvc.dll -- (ezGOSvc)
SRV - [2011.02.28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011.02.25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2009.12.23 23:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2008.02.19 09:12:18 | 000,537,256 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxbkcoms.exe -- (lxbk_device)
SRV - [2008.01.19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007.05.31 10:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007.05.31 10:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2007.03.12 18:54:10 | 000,931,376 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2007.02.06 03:13:14 | 000,094,208 | ---- | M] () [Auto | Running] -- C:\Program Files\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService)
SRV - [2006.12.29 01:17:50 | 000,123,248 | ---- | M] () [Auto | Running] -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe -- (spmgr)
SRV - [2006.11.01 07:40:16 | 000,077,824 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)


========== Driver Services (SafeList) ==========

DRV - [2011.05.17 16:11:18 | 000,436,792 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.04.11 06:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009.01.13 09:45:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008.10.09 16:42:42 | 000,017,408 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2007.12.21 09:21:56 | 000,033,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2007.12.21 09:20:14 | 000,030,216 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\easdrv.sys -- (easdrv)
DRV - [2007.12.21 09:19:54 | 000,039,944 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\eamon.sys -- (eamon)
DRV - [2007.11.03 01:12:32 | 000,041,456 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD\000.fcl -- ({95808DC4-FA4A-4C74-92FE-5B863F82066B})
DRV - [2007.03.12 18:54:10 | 000,038,576 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDRm.sys -- (incdrm)
DRV - [2007.03.12 18:54:00 | 000,037,040 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDPass.sys -- (InCDPass)
DRV - [2007.03.12 18:53:50 | 000,118,064 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\Windows\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2007.02.02 09:09:39 | 002,385,920 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2007.01.03 00:37:48 | 000,011,120 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Program Files\P4G\WCPU.sys -- (WCPU)
DRV - [2006.12.14 17:11:57 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2006.11.16 04:02:19 | 000,015,216 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys -- (ghaio)
DRV - [2006.11.14 21:42:45 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006.11.09 00:44:20 | 000,015,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\ASUS\ASUS Live Update\SYS64\lvupdtio.sys -- (lvupdtio)
DRV - [2006.11.06 12:01:19 | 000,051,200 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006.11.02 11:50:17 | 000,041,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2006.11.02 09:30:56 | 000,044,544 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2006.11.02 09:30:54 | 001,781,760 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel(R)
DRV - [2006.10.14 05:04:33 | 004,422,560 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2005.08.02 01:45:00 | 000,064,896 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2005.05.26 18:19:18 | 000,839,724 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/skinit/icq/
IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\URLSearchHook: {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - File not found
IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.centrum.cz/skinit/icq/"
FF - prefs.js..extensions.enabledItems: ar@dictionaries.addons.mozilla.org:2.0.20080110
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.8
FF - prefs.js..extensions.enabledItems: cs@dictionaries.addons.mozilla.org:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... r=1.1.9&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "resource:/browserconfig.properties"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_result ... id=afex&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.08.21 20:28:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.20\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.08.21 20:28:37 | 000,000,000 | ---D | M]

[2008.09.02 15:14:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Milan\AppData\Roaming\Mozilla\Extensions
[2011.08.21 17:47:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions
[2009.09.04 19:11:07 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.05.18 19:38:41 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2009.12.27 21:28:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008.12.31 00:18:19 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2008.10.14 22:02:40 | 000,000,000 | ---D | M] (Arabic spell-checking dictionary) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\ar@dictionaries.addons.mozilla.org
[2008.10.14 22:02:39 | 000,000,000 | ---D | M] (České slovníky pro kontrolu pravopisu) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\cs@dictionaries.addons.mozilla.org
[2009.12.27 21:28:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\staged-xpis
[2011.08.21 17:47:08 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-1.xml
[2009.04.29 14:51:47 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-10.xml
[2009.06.20 14:14:38 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-11.xml
[2009.07.25 15:19:19 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-12.xml
[2009.09.17 17:59:49 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-13.xml
[2009.10.14 20:52:40 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-14.xml
[2009.11.17 20:18:33 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-15.xml
[2009.12.27 23:03:31 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-16.xml
[2010.01.27 20:28:14 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-17.xml
[2010.02.20 16:37:13 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-18.xml
[2010.04.11 12:19:14 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-19.xml
[2008.07.10 15:19:57 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-2.xml
[2011.07.25 19:34:36 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-20.xml
[2011.07.25 20:10:02 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-21.xml
[2007.07.31 00:12:43 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-3.xml
[2008.10.14 22:03:21 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-4.xml
[2008.12.08 11:11:15 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-5.xml
[2008.12.18 18:24:34 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-6.xml
[2007.07.31 00:33:05 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-7.xml
[2009.04.20 13:27:09 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-8.xml
[2009.04.23 21:46:07 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-9.xml
[2011.05.18 19:38:41 | 000,000,168 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.gif
[2011.05.18 19:38:41 | 000,000,618 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.src
[2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.xml
[2009.06.30 19:54:00 | 000,001,632 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\live-search.xml
[2008.12.31 00:18:09 | 000,003,915 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\sweetim.xml
[2011.07.11 17:15:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009.07.18 18:55:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.07.11 17:15:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2008.09.02 15:14:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\talkback@mozilla.org
[2011.07.11 17:14:31 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011.07.25 19:34:16 | 000,000,638 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\jyxo-cz.xml
[2011.07.25 19:34:16 | 000,001,687 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
[2011.07.25 19:34:16 | 000,001,367 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\seznam-cz.xml
[2011.07.25 19:34:16 | 000,000,654 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\slunecnice-cz.xml
[2011.07.25 19:34:16 | 000,001,179 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2011.08.22 20:04:41 | 000,000,726 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (XTTBPos00 Class) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - Reg Error: Value error. File not found
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Search Assistant BHO) - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - Reg Error: Value error. File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4 - HKLM..\Run: [egui] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [tray_ico] File not found
O4 - HKLM..\Run: [tray_ico2] File not found
O4 - HKLM..\Run: [tray_ico3] File not found
O4 - HKLM..\Run: [tray_ico4] File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [] File not found
O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [EPSON Stylus DX4400 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [ICQ] C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [T-Mobile Communication Centre] C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe (Gemfor s.r.o.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Milan\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O24 - Desktop BackupWallPaper: C:\Users\Milan\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta galerie Windows Fotogalerie.jpg
O31 - SafeBoot: AlternateShell - services32.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{38122e00-b829-11e0-80b5-001bfcf4333c}\Shell - "" = AutoRun
O33 - MountPoints2\{38122e00-b829-11e0-80b5-001bfcf4333c}\Shell\AutoRun\command - "" = F:\PcOptions.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: ezGOSvc - C:\Windows\System32\ezGOSvc.dll ()

Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

========== Files/Folders - Created Within 7 Days ==========

[2011.08.22 20:03:52 | 000,000,000 | ---D | C] -- C:\Users\Milan\Desktop\RK_Quarantine
[2011.08.22 20:02:42 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Milan\Desktop\OTL.exe
[2011.08.22 19:36:44 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.08.22 19:36:43 | 000,000,000 | ---D | C] -- C:\rsit
[2011.08.22 17:56:34 | 000,000,000 | -H-D | C] -- C:\Windows\update.7.1
[2011.08.22 17:56:23 | 000,000,000 | -H-D | C] -- C:\Windows\update.2
[2011.08.22 17:13:36 | 000,000,000 | ---D | C] -- C:\Windows\ufa
[2011.08.22 17:13:36 | 000,000,000 | ---D | C] -- C:\Windows\rpcminer
[2011.08.22 17:13:36 | 000,000,000 | ---D | C] -- C:\Windows\phoenix
[2011.08.22 16:49:16 | 000,000,000 | -H-D | C] -- C:\Windows\update.5.0
[2011.08.21 20:26:27 | 000,000,000 | ---D | C] -- C:\Windows\av_ico
[2011.08.21 20:24:34 | 000,000,000 | -H-D | C] -- C:\Windows\update.1
[2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-2-0-lnk
[2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-2-0
[2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-15-0-lnk
[2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-15-0
[2011.08.19 14:28:32 | 000,718,208 | ---- | C] (EasyBits Media) -- C:\Windows\System32\ezGOSvcApp.exe
[2011.08.19 14:09:54 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2008.02.19 11:12:20 | 000,385,704 | ---- | C] ( ) -- C:\Windows\System32\lxbkih.exe
[2008.02.19 11:12:18 | 000,537,256 | ---- | C] ( ) -- C:\Windows\System32\lxbkcoms.exe
[2008.02.19 11:12:16 | 000,381,608 | ---- | C] ( ) -- C:\Windows\System32\lxbkcfg.exe
[2006.11.06 18:37:46 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxbkpmui.dll
[2006.11.06 18:35:50 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxbkserv.dll
[2006.11.06 18:28:08 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxbkcomm.dll
[2006.11.06 18:26:14 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxbklmpm.dll
[2006.11.06 18:24:44 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxbkiesc.dll
[2006.11.06 18:21:48 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxbkpplc.dll
[2006.11.06 18:20:48 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxbkcomc.dll
[2006.11.06 18:20:14 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxbkprox.dll
[2006.11.06 18:12:44 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxbkinpa.dll
[2006.11.06 18:11:58 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\lxbkusb1.dll
[2006.11.06 18:07:04 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxbkhbn3.dll
[1 C:\Users\Milan\Desktop\*.tmp files -> C:\Users\Milan\Desktop\*.tmp -> ]

========== Files - Modified Within 7 Days ==========

[2011.08.22 20:04:41 | 000,000,726 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011.08.22 19:56:36 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Milan\Desktop\OTL.exe
[2011.08.22 19:55:38 | 000,569,856 | ---- | M] () -- C:\Users\Milan\Desktop\RogueKiller.exe
[2011.08.22 19:17:22 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011.08.22 19:17:22 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011.08.22 19:07:45 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2011.08.22 18:41:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.08.22 18:30:14 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011.08.22 18:29:17 | 000,000,734 | ---- | M] () -- C:\Windows\System32\drivers\etc\hîsts
[2011.08.22 18:24:27 | 000,000,201 | ---- | M] () -- C:\Windows\info1
[2011.08.22 18:23:42 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe
[2011.08.22 18:18:28 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
[2011.08.22 17:56:36 | 000,904,792 | ---- | M] () -- C:\Windows\geoiplist.rar
[2011.08.22 17:56:36 | 000,246,272 | ---- | M] () -- C:\Windows\unrar.exe
[2011.08.22 17:43:49 | 000,000,270 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011.08.22 17:13:35 | 005,589,370 | ---- | M] () -- C:\Windows\phoenix.rar
[2011.08.22 17:13:35 | 000,182,617 | ---- | M] () -- C:\Windows\ufa.rar
[2011.08.22 17:13:34 | 001,075,284 | ---- | M] () -- C:\Windows\rpcminer.rar
[2011.08.22 16:49:07 | 000,000,000 | ---- | M] () -- C:\Windows\loader2.exe_ok
[2011.08.22 16:48:52 | 000,137,728 | ---- | M] () -- C:\Windows\systemup.exe
[2011.08.22 16:42:55 | 000,258,048 | ---- | M] () -- C:\Windows\sysdriver32_.exe
[2011.08.22 16:42:55 | 000,258,048 | ---- | M] () -- C:\Windows\sysdriver32.exe
[2011.08.21 20:11:06 | 001,213,440 | ---- | M] () -- C:\Windows\services32.exe
[2011.08.19 14:11:56 | 000,610,724 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2011.08.19 14:11:56 | 000,598,900 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.08.19 14:11:56 | 000,104,914 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.08.19 14:11:55 | 000,119,308 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[1 C:\Users\Milan\Desktop\*.tmp files -> C:\Users\Milan\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011.08.22 20:02:42 | 000,569,856 | ---- | C] () -- C:\Users\Milan\Desktop\RogueKiller.exe
[2011.08.22 18:18:33 | 000,232,960 | ---- | C] () -- C:\Windows\l1rezerv.exe
[2011.08.22 17:56:31 | 004,636,907 | ---- | C] () -- C:\Windows\geoiplist
[2011.08.22 17:56:30 | 000,904,792 | ---- | C] () -- C:\Windows\geoiplist.rar
[2011.08.22 17:43:49 | 000,000,270 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011.08.22 17:13:35 | 000,246,272 | ---- | C] () -- C:\Windows\unrar.exe
[2011.08.22 17:13:35 | 000,182,617 | ---- | C] () -- C:\Windows\ufa.rar
[2011.08.22 17:13:34 | 005,589,370 | ---- | C] () -- C:\Windows\phoenix.rar
[2011.08.22 17:13:34 | 001,075,284 | ---- | C] () -- C:\Windows\rpcminer.rar
[2011.08.22 16:49:07 | 000,000,000 | ---- | C] () -- C:\Windows\loader2.exe_ok
[2011.08.22 16:49:00 | 000,137,728 | ---- | C] () -- C:\Windows\systemup.exe
[2011.08.22 16:48:53 | 000,000,201 | ---- | C] () -- C:\Windows\info1
[2011.08.22 16:43:27 | 000,258,048 | ---- | C] () -- C:\Windows\sysdriver32_.exe
[2011.08.22 16:43:09 | 000,258,048 | ---- | C] () -- C:\Windows\sysdriver32.exe
[2011.08.21 20:11:28 | 001,213,440 | ---- | C] () -- C:\Windows\services32.exe
[2011.08.19 14:28:32 | 000,073,600 | ---- | C] () -- C:\Windows\System32\ezGOSvc.dll
[2011.06.02 15:20:02 | 000,000,680 | ---- | C] () -- C:\Users\Milan\AppData\Local\d3d9caps.dat
[2011.05.19 14:30:56 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010.08.22 15:51:57 | 000,000,785 | ---- | C] () -- C:\Windows\Rtcw.INI
[2010.08.06 16:33:21 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010.08.06 16:33:18 | 000,022,328 | ---- | C] () -- C:\Users\Milan\AppData\Roaming\PnkBstrK.sys
[2010.08.06 16:33:05 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010.08.06 16:33:01 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010.08.06 16:32:57 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2009.09.12 18:14:37 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009.09.12 18:14:36 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009.04.17 16:19:52 | 000,004,096 | -H-- | C] () -- C:\Users\Milan\AppData\Local\keyfile3.drm
[2008.08.29 13:41:10 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008.06.21 23:15:50 | 000,000,151 | ---- | C] () -- C:\Windows\PhotoSnapViewer.INI
[2008.04.08 13:04:33 | 000,111,932 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2008.04.08 13:04:33 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat
[2008.04.08 13:04:33 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat
[2008.04.08 13:04:33 | 000,026,154 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2008.04.08 13:04:33 | 000,024,903 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat
[2008.04.08 13:04:33 | 000,021,390 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat
[2008.04.08 13:04:33 | 000,020,148 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2008.04.08 13:04:33 | 000,011,811 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat
[2008.04.08 13:04:33 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat
[2008.04.08 13:04:33 | 000,001,146 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_DU.dat
[2008.04.08 13:04:33 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat
[2008.04.08 13:04:33 | 000,001,139 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat
[2008.04.08 13:04:33 | 000,001,136 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat
[2008.04.08 13:04:33 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat
[2008.04.08 13:04:33 | 000,001,129 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat
[2008.04.08 13:04:33 | 000,001,120 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_IT.dat
[2008.04.08 13:04:33 | 000,001,107 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_GE.dat
[2008.04.08 13:04:33 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat
[2008.04.08 13:04:33 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2008.04.08 12:57:20 | 000,000,026 | ---- | C] () -- C:\Windows\CDE DX4400DEFGIPS.ini
[2008.04.03 23:34:47 | 000,000,073 | ---- | C] () -- C:\Windows\EurekaLog.ini
[2008.03.27 21:23:36 | 000,000,384 | ---- | C] () -- C:\Windows\ODBC.INI
[2008.03.27 01:17:13 | 000,001,015 | ---- | C] () -- C:\Windows\eReg.dat
[2008.03.19 19:01:43 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008.03.16 14:20:08 | 000,000,101 | ---- | C] () -- C:\Windows\lexstat.ini
[2008.03.08 12:01:09 | 000,000,903 | ---- | C] () -- C:\Windows\disney.ini
[2008.02.16 21:16:44 | 000,063,488 | ---- | C] () -- C:\Windows\System32\Eztw32.dll
[2008.02.13 01:14:40 | 000,000,032 | ---- | C] () -- C:\ProgramData\ezsid.dat
[2008.02.12 22:54:17 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2008.02.08 11:01:48 | 000,000,546 | ---- | C] () -- C:\Windows\System32\ABX51R.DAT
[2008.02.07 23:13:02 | 000,018,432 | ---- | C] () -- C:\Users\Milan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.02.07 20:50:25 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2008.02.07 20:26:40 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini
[2008.02.07 19:11:29 | 000,045,056 | ---- | C] () -- C:\Windows\System32\acovcnt.exe
[2007.12.21 09:21:56 | 000,033,800 | ---- | C] () -- C:\Windows\System32\drivers\epfwtdir.sys
[2007.07.31 00:26:24 | 000,000,552 | ---- | C] () -- C:\Users\Milan\AppData\Local\d3d8caps.dat
[2007.07.31 00:24:28 | 000,000,745 | ---- | C] () -- C:\Windows\CoD.INI
[2007.04.21 10:35:21 | 000,610,724 | ---- | C] () -- C:\Windows\System32\perfh005.dat
[2007.04.21 10:35:21 | 000,286,912 | ---- | C] () -- C:\Windows\System32\perfi005.dat
[2007.04.21 10:35:21 | 000,119,308 | ---- | C] () -- C:\Windows\System32\perfc005.dat
[2007.04.21 10:35:21 | 000,034,724 | ---- | C] () -- C:\Windows\System32\perfd005.dat
[2007.04.21 10:29:18 | 000,000,010 | ---- | C] () -- C:\Windows\System32\ABLKSR.ini
[2007.04.21 09:47:06 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2007.02.07 18:57:50 | 000,039,899 | ---- | C] () -- C:\Windows\System32\rtsicis.ini
[2007.02.02 09:01:29 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2007.02.02 08:38:31 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2007.01.30 05:21:33 | 000,128,813 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2007.01.22 10:49:34 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxbkcoin.dll
[2006.12.05 22:05:06 | 000,114,688 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006.11.30 15:34:24 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxbkutil.dll
[2006.11.02 14:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006.11.02 14:44:53 | 000,371,800 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006.11.02 12:33:01 | 000,598,900 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006.11.02 12:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006.11.02 12:33:01 | 000,104,914 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006.11.02 12:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006.11.02 12:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006.11.02 10:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006.11.02 10:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006.11.02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006.11.02 09:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006.03.09 12:57:59 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | ---- | C] () -- C:\Windows\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,778,240 | ---- | C] () -- C:\Windows\System32\DivXsm.exe
[2005.10.14 12:56:50 | 000,761,856 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- C:\Windows\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ogg.dll
[2005.10.05 14:19:32 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxbkvs.dll
[2005.09.13 17:27:10 | 000,061,440 | ---- | C] () -- C:\Windows\System32\lxbkcnv5.dll
[2005.07.23 06:30:20 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
[2005.05.26 18:12:26 | 000,065,536 | ---- | C] () -- C:\Windows\sm56spn.dll
[2005.05.26 18:12:26 | 000,065,536 | ---- | C] () -- C:\Windows\sm56itl.dll
[2005.05.26 18:12:26 | 000,065,536 | ---- | C] () -- C:\Windows\sm56ger.dll
[2005.05.26 18:12:26 | 000,065,536 | ---- | C] () -- C:\Windows\sm56fra.dll
[2005.05.26 18:12:26 | 000,065,536 | ---- | C] () -- C:\Windows\sm56eng.dll
[2005.05.26 18:12:26 | 000,065,536 | ---- | C] () -- C:\Windows\sm56brz.dll
[2005.05.26 18:12:26 | 000,049,152 | ---- | C] () -- C:\Windows\sm56jpn.dll
[2005.05.26 18:12:26 | 000,045,056 | ---- | C] () -- C:\Windows\sm56cht.dll
[2005.05.26 18:12:26 | 000,045,056 | ---- | C] () -- C:\Windows\sm56chs.dll
[2003.04.09 15:38:04 | 000,005,664 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI

========== LOP Check ==========

[2011.03.26 18:38:54 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\com.lightmaker.deagostini.ScrapBook.29F1EDFB1A6EC94F998B5392F8031DD941FC022D.1
[2009.09.09 18:01:44 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\com.lightmaker.deagostini.ScrapBook.D45F7F2B1F9C3FBA2126914CB42B3E19064D325F.1
[2008.05.15 12:16:01 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\EPSON
[2010.04.28 18:38:42 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\GHISLER
[2011.04.30 12:35:20 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\Glory of the Roman Empire
[2011.08.22 17:27:10 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\go
[2011.08.03 00:03:52 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\ICQ
[2008.05.17 13:10:08 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\ICQ Toolbar
[2008.02.25 20:54:27 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\InterTrust
[2011.04.21 15:19:25 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\NEM3000
[2010.07.28 14:37:59 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\Playrix Entertainment
[2011.07.21 22:29:46 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\Windows Live Writer
[2011.08.22 18:30:17 | 000,032,564 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< >

< savembr0 >

< >

< md5start >

< adp3132.sys >

< AGP440.sys >

< ahcix86.sys >

< ahcix86s.sys >

< atapi.sys >

< autochk.exe >

< cdrom.sys >

< cngaudit.dll >

< cryptsvc.dll >

< eNetHook.dll >

< eventlog.dll >

< explorer.exe >

< hal.dll >

< Changer.sys >

< iaStor.sys >

< iastorv.sys >

< IdeChnDr.sys >

< isapnp.sys >

< JakNDis.sys >

< KR10N.sys >

< logevent.dll >

< lsass.exe >

< mv61xx.sys >

< ndis.sys >

< netlogon.dll >

< ntelogon.dll >

< nvata.sys >

< nvatabus.sys >

< nvgts.sys >

< nvraid.sys >

< nvrd32.sys >

< nvstor.sys >

< nvstor32.sys >

< scecli.dll >

< sceclt.dll >

< smss.exe >

< svchost.exe >

< symmpi.sys >

< tcpip.sys >

< userinit.exe >

< vaxscsi.sys >

< viamraid.sys >

< viasraid.sys >

< ViPrt.sys >

< winlogon.exe >

< ws2_32.dll >

< md5stop >

< >

< %systemroot%. U s >

< %SYSTEMDRIVE%.exe >

< %ALLUSERSPROFILE%Application Data. >
[2006.11.02 14:59:44 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data

< %ALLUSERSPROFILE%Application Data.exe s >

< %APPDATA%. >

< %APPDATA%.exe s >

< %systemroot%. mp s >

< %systemroot%system32.dll lockedfiles >

< %systemroot%Tasks.job lockedfiles >

< %systemroot%system32drivers.sys lockedfiles >

< %systemroot%System32config.sav >

< %systemroot%system32.dll lockedfiles >

< %systemroot%system32drivers.sys 3 >

< %systemroot%system32. 3 >

< %SYSTEMDRIVE%.exe >

< >

< HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun s >

< >

< type cboot.ini test.txt c >

< %SystemDrive%PhysicalMBR.bin md5 >

< End of report >

LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

Re: FB vir, restartování NTB

#8 Příspěvek od LukassM »

OTL Extras logfile created on: 22.8.2011 20:08:56 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Milan\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1,87 Gb Total Physical Memory | 1,01 Gb Available Physical Memory | 53,91% Memory free
3,99 Gb Paging File | 2,95 Gb Available in Paging File | 74,01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55,89 Gb Total Space | 5,72 Gb Free Space | 10,23% Space Free | Partition Type: NTFS
Drive D: | 49,06 Gb Total Space | 12,89 Gb Free Space | 26,28% Space Free | Partition Type: NTFS
Drive F: | 243,73 Mb Total Space | 182,91 Mb Free Space | 75,05% Space Free | Partition Type: FAT

Computer Name: MILANPC-PRACE | User Name: Milan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
"FirewallOverride" = 1
"DisableThumbnailCache" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{044ABAFE-DF71-403E-9A7D-E900C76EBC5B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{0A8DE038-D0AA-4573-B5CA-B626F7C4D34C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{104DA69B-0E9F-4204-823D-E4E2E16DAB2B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{28ED7839-9DA4-4786-8645-54AD00BB81DB}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2FC70491-845D-422A-B74C-2FC012E55BB6}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{379575AE-BEBD-473D-A912-AE9BC8995E01}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4A8DB4FB-963F-4077-B7B1-6DBD71A6BBB6}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{506F3205-9557-4053-92A8-03AD348DE960}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{53196168-5EE4-4B77-967E-EE78246F196F}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{58C09C47-8959-4E03-9907-4F412D057D95}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{71502D75-3A31-4AAD-A2E4-2D936BA2786C}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{7601FB46-5DAA-4AF9-855B-67B480FC7417}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{851B5852-3DCB-425A-9469-C6B245CDCA1A}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{908579B9-B302-4003-99A5-70F9FA5FCBFD}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{9C666AEC-E9B5-4ABA-A78A-65F34FAC8FF7}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{ADBEC803-FF2A-476B-A52A-DEDD1F04FF52}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{B67BC366-D911-4DE8-8E68-9F65A61B4188}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{B9795AE3-D239-4C1B-A203-B2E5424AE581}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{C2151AFD-4873-40F8-809F-9AE474D64628}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{DA0F44B0-8E6B-4B61-BBE4-1665F5B29BB1}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{DCA4CE1E-36E8-4AFC-90B1-C325407A0544}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{EF4D6F75-2B2E-41EC-A975-481A4F8EC9AF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{000CCFF7-68AB-4BCB-8DAF-CED37DFD5867}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{087D0859-53BE-4C9B-AA7F-6BF8DD904215}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{0906D3CF-E798-4B67-A10A-8BD62B959D8E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{09AAD4A8-3E40-434E-9F67-F17EE7B6FD88}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{0C00C29B-2F20-4DFC-A34B-C9F6E4BFB1C1}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{0CCCD3DE-D8E9-4180-B5BA-6092DCEAB73F}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1040204F-59F3-4D70-9CC1-C5AD7E6D91DD}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{11AA34BC-2509-433B-BD6D-A947783D963A}" = protocol=6 | dir=in | app=c:\windows\system32\lxbkcoms.exe |
"{12C4CA10-9957-45C3-87A8-B763DFE469DB}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{145B48E3-03F7-49DB-B94F-26C32F3484B9}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{19E4D39A-2D43-4CBE-8C0A-D5900A60212C}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1BB5C023-A6DB-44CC-9B38-D34430E5817E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{1E736F02-D601-46E0-A7B1-7A2CC7B02A04}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{1E878990-66F9-465D-ACDD-AA3B8FDB4E66}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{2119FD5D-3873-4324-B66A-D60D93C038A2}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2215F944-4615-4F2C-BEC3-F75E762237A8}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{22596C9B-15BB-4374-ADCB-4DF1A8CBA312}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{22D21FC4-DC56-4D18-B73A-6F1940B378F3}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{2593F2FE-84B9-4550-9733-3DB41E459FDE}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{278E68B3-0888-4E03-B306-925B5931AB68}" = protocol=17 | dir=in | app=c:\windows\system32\lxbkcoms.exe |
"{2A3E3EFB-10A7-4F85-BEAA-D4F2B6FD4E65}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{2A6461D7-9E29-46C8-9AA3-BECE3B5F6B34}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2B0494C9-0E64-4924-8481-0B08E337234E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{2FE69109-06C0-46B2-8210-9993C3D88910}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{3044EF08-052B-4827-86BF-C0A229E1B617}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbkpswx.exe |
"{33E9453F-E4B8-40F4-8092-E9855494C2F8}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{350E2254-A12A-4BA3-8F86-1AE0A782FDE4}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{363A50AE-A972-4EF9-B9C9-5A319FA8AF18}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{369877A7-6CC2-4F25-99F1-DBA33590126A}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{3B25DB92-A361-4CD1-8849-B5EAFE42CCAD}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{3DFA7F63-9B71-4CF9-AC09-AC96CF14FB69}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{3F78EF15-A6BF-46A9-8471-56BACB6DFEB5}" = protocol=17 | dir=in | app=d:\program files\microsoft games\zoo tycoon 2\zt.exe |
"{400A0A74-D7B8-40F1-B9DB-873FB1C4A108}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{41FACE3F-03EB-40C0-AEFF-743710D8F251}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{42737CC5-E06F-467E-ADA1-120E2973A9BD}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{4519B63E-21FB-4642-9548-E57C96A59D93}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{45BD6533-426B-4808-98AF-127C45589CF3}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{46B8D830-F868-4CFF-A093-C629488A216E}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{4C583B44-2940-48B6-94B5-8520CD5EDBBF}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbkpswx.exe |
"{4C5AF920-BC89-479F-A5E0-8EC87C06603E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{575B12DC-2745-4FE9-B97C-9F7122C152FC}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{57D0858A-4B4D-446F-80C6-8A74C6DAD6AC}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{596DFB86-9B7E-4E6D-BC64-2B5E829468D5}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5A32E6CA-FF0A-43A7-8F73-B61E82147170}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5C41BA91-5DF9-44F8-899C-3C28F82C6A01}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{6024F76B-8CD1-463C-8C1C-2C8611F396D0}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{64D8BAD4-AD58-4CEF-9906-812C4A670648}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{665B917D-3801-4B41-91E8-155DEB8B717E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{66C9283E-8FBB-458D-AC3A-C207D89F3015}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{67ED4AB3-BF0C-410A-9EE8-DF13F26DF2DC}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{69042708-5EBB-4F8C-86F6-01385EA3FD55}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{6C6AAE3E-2B61-4288-939A-5687C15012B5}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{6F7B7DBE-0E03-4204-BF7A-17F081BA60F7}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{6FBBB4DC-E08E-49BA-97B4-78FAD0C6CE26}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{702F6064-8501-4A8C-8FB8-9C2941E7866A}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{71A53FE4-5A97-410A-8DEF-A0D403925406}" = protocol=6 | dir=in | app=d:\program files\microsoft games\zoo tycoon 2\zt.exe |
"{75D046AD-B851-41EB-AD02-9876B68ADB16}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{79C1BB8B-3BF9-447D-B036-65E721D5FC53}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7AE1AD51-C153-4967-AECA-A7011A25C037}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{7CEC0190-B6EF-41C5-888B-E042DF9E579D}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{80BAF1A2-7900-4D0F-838D-EA799E070AE9}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{8291E80C-98A4-4E57-9FA4-D761177D8D86}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{84850AE4-D039-4898-B674-895217CB90DA}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{89EB6793-C257-442E-9235-68931819BB4E}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8DE483E1-6271-499A-9256-A46141490617}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{8E100C49-2858-48EB-9158-CDDBFF92B245}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8EECE0D3-7778-4DFA-9E4D-D9D8E14DF682}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{9247DB04-27E5-44FF-9FDB-7049C2824239}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{926E6BC8-FE02-456F-AD72-A4DC362C0F98}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{93391141-23D4-4952-A31C-E00157CF5CB2}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{93CDADA4-3BBB-4226-A937-B37C447A58FA}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9784B424-B77F-4F15-BB44-D37410793344}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{979788CC-5D16-4278-A1A8-FAE5910C7D9B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9849AE81-F1A8-4C3A-B07A-B0A376BDC98B}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{9AC7A99E-4CB0-44B6-AC50-DC0CC86D917F}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{9B4FE823-9919-4B6C-B9FF-02A5AB388D80}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A0277A71-26A3-4A22-9ACB-30E893E52562}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A03D6472-AECA-4BC9-A5BA-092C10BC529A}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A0DB5934-658C-47DE-8A36-E90EFB021668}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{ABCD2A01-334A-4BD6-95DF-60473B614012}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{AD13ACCC-DE99-4EA6-877F-3A2A636623BA}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{AD67EBB5-0F9D-4AA8-B225-E9501943EA90}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{AE313CF2-9710-462D-8CA8-D73BE4A006F1}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{AFAFCB08-F01E-4B38-8443-F271D21AC1FD}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{AFD022DC-68A4-445E-BDC6-DDC1A859CCFD}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B46F6C16-901E-4E8E-B088-7275603AE14D}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B685D141-53D3-4427-A62C-BD35AAB7D7D3}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B8BD0F1C-492C-4ECC-96FC-85C75FE494CF}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{B8DA03FC-EAD9-4DCD-B4F7-2FB33CCD0A5E}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B9118F86-A7B5-4F92-B90D-48C05AFE5CB2}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{B9B99687-A630-40ED-A3A8-02DC5176EB04}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{BBC8DFA4-136E-4297-9B2F-32741B710172}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C03C1CE9-36F4-47B4-A2D3-466C6F22232C}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C05D8A2D-8F1A-4B34-8087-9341B98AA7BA}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C0D69ECC-A500-4259-A428-1FE41BF7A539}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C35B47F5-71D8-408D-9429-9819B610D415}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C61C676A-0272-4FEF-A610-C163EE5B3DAB}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{C9A784C8-EE2E-4A1E-A7C0-6155968608D0}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CAEE4872-82D7-4905-BE08-2903AA04E42B}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CCDBC4F6-7E63-4223-ACAB-16E586E2D4D7}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CF018933-73D9-4A60-ADD8-BEC289EB468E}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{CF393D9F-7823-4D59-84B0-1FFF36561F09}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D18EA3E0-A232-4B0A-9402-5F7E9B5D99CD}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D3021FAF-7BFB-460D-88C4-829FF0089B41}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{D4992BA5-07EC-498B-8392-CBDA250C3E33}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D4DF42C0-5C22-40CE-B9E9-45B807C8B56A}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D804AF3C-4232-43D7-A7EF-CA1B5C5E21BE}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D86CB88B-5D4B-4400-8264-4DC010591DB8}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{DCE5D4CA-FD78-4325-ADE4-ABCBD4D59D5C}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{DF6A68B8-1D59-41C6-ACB8-C2D96CC08D5E}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{E46A625E-8EAF-435A-86F0-4B87080D81BE}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{EA9FAC13-8BB7-4E98-9E56-7C6E09DDD53E}" = protocol=6 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{EAE930E1-CC1E-41F7-918C-AC27A7CAF390}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{EC3909C9-9E00-462F-9AEA-5EE8ED6E13BC}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{ED2A6496-2184-4F5B-A7DF-A6008F681A22}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{EECC2446-1B74-4858-9458-7651C2872E35}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{F98D43D1-51B5-4D2B-8C4D-1DD32E9018C3}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F9BFC2FB-3CE8-4D50-BD27-3C3B51A7403D}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FA5E11AB-645B-4903-8051-1C705340A07C}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{FA96C323-2590-4EEA-A56C-A062AD13B12D}" = protocol=17 | dir=in | app=c:\program files\icq7.5\icq.exe |
"{FEFA998E-65BB-4BA8-BC36-D3C010AA3198}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"TCP Query User{1870209E-51D2-4CE3-AD74-37EA29A2528F}D:\program files\microsoft games\jazz jackrabbit\jazz2.exe" = protocol=6 | dir=in | app=d:\program files\microsoft games\jazz jackrabbit\jazz2.exe |
"TCP Query User{3599B3DC-55B0-4D43-979E-900BAB70EBAE}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{519CBCE6-ADD9-4D5E-A998-8C175D58794E}C:\program files\icq6.5\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6.5\icq.exe |
"TCP Query User{5D288891-957E-4FAC-AE82-ECFE468DE3D8}D:\program files\microsoft games\medal off honor\mohaa.exe" = protocol=6 | dir=in | app=d:\program files\microsoft games\medal off honor\mohaa.exe |
"TCP Query User{9C66A182-9D98-4123-AA0B-141C908C1A64}C:\program files\icq6\icq.exe" = protocol=6 | dir=in | app=c:\program files\icq6\icq.exe |
"TCP Query User{B6E09913-D683-4B4F-BA2B-D322BA62B5C4}C:\program files\ea games\mohaa\mohaa.exe" = protocol=6 | dir=in | app=c:\program files\ea games\mohaa\mohaa.exe |
"TCP Query User{D16D2CFF-2087-4116-9546-F3A49C4B2E84}D:\simon a schuster\skutečná válka\realwar.exe" = protocol=6 | dir=in | app=d:\simon a schuster\skutečná válka\realwar.exe |
"TCP Query User{D34E3822-7618-4CBB-A88C-289C39D4239B}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{D4331D18-27B7-4237-8950-1286D1A82B8F}D:\hry\return to castle wolfenstein\wolfmp.exe" = protocol=6 | dir=in | app=d:\hry\return to castle wolfenstein\wolfmp.exe |
"TCP Query User{E3B5BF1D-D7D4-4285-89D9-18EE718BE66A}H:\wow-3.3.2.11403-to-3.3.3.11685-engb-downloader.exe" = protocol=6 | dir=in | app=h:\wow-3.3.2.11403-to-3.3.3.11685-engb-downloader.exe |
"TCP Query User{ED9EFAF3-7C0C-48F8-9D41-B150A2F03382}D:\program files\setlers iv\exe\s4_main.exe" = protocol=6 | dir=in | app=d:\program files\setlers iv\exe\s4_main.exe |
"UDP Query User{28ABEF4F-72E2-46C2-8B23-E2D14B1ADEC4}C:\program files\icq6\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6\icq.exe |
"UDP Query User{69A42A88-86DF-4172-B216-FCE0CC88464C}D:\hry\return to castle wolfenstein\wolfmp.exe" = protocol=17 | dir=in | app=d:\hry\return to castle wolfenstein\wolfmp.exe |
"UDP Query User{792115C3-BD59-4649-AEC8-89D23EB41701}D:\program files\microsoft games\jazz jackrabbit\jazz2.exe" = protocol=17 | dir=in | app=d:\program files\microsoft games\jazz jackrabbit\jazz2.exe |
"UDP Query User{7D372947-8B36-426A-BFF2-9D25CB2326AD}C:\program files\ea games\mohaa\mohaa.exe" = protocol=17 | dir=in | app=c:\program files\ea games\mohaa\mohaa.exe |
"UDP Query User{9205BC59-ECDF-46CE-9A0C-6676FA007C00}D:\simon a schuster\skutečná válka\realwar.exe" = protocol=17 | dir=in | app=d:\simon a schuster\skutečná válka\realwar.exe |
"UDP Query User{B7797C93-8A8D-45CD-A858-CCCDF3257263}D:\program files\setlers iv\exe\s4_main.exe" = protocol=17 | dir=in | app=d:\program files\setlers iv\exe\s4_main.exe |
"UDP Query User{B9CF53DE-6985-4DFB-ACAF-D8B2B6706473}C:\program files\icq6.5\icq.exe" = protocol=17 | dir=in | app=c:\program files\icq6.5\icq.exe |
"UDP Query User{C43105B1-9F42-4DAD-85A2-9F781ACF0360}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"UDP Query User{D3E589C1-D02B-49B9-BCAB-548813D68DD2}H:\wow-3.3.2.11403-to-3.3.3.11685-engb-downloader.exe" = protocol=17 | dir=in | app=h:\wow-3.3.2.11403-to-3.3.3.11685-engb-downloader.exe |
"UDP Query User{EB40E719-5BC4-47CD-B6E4-A9D489D1EECC}D:\program files\microsoft games\medal off honor\mohaa.exe" = protocol=17 | dir=in | app=d:\program files\microsoft games\medal off honor\mohaa.exe |
"UDP Query User{F18D3FCA-BC04-44C8-BC12-78E21C9DB5D9}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"%Product_Name% 4.2F " = Faktury 4.2F
"{01FA3608-A97F-1836-B764-39E344522FBE}" = Hannah Montana Tajný Deník
"{03906667-7B1D-6A57-C807-1F3C175FC085}" = Hannah Montana Tajný Deník
"{05D67915-50EC-56C9-7148-552F8D205383}" = CCC Help German
"{08C69626-1E29-7EE2-E122-D475D7BAAF0B}" = Catalyst Control Center Localization Hungarian
"{09E9F3B1-2965-3D8B-F624-2F44D99B53B0}" = Catalyst Control Center Graphics Light
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{0E4E7AB0-6FFB-4C76-FD74-810DE985D518}" = Catalyst Control Center Localization Greek
"{10D3701B-1463-0C2F-748E-3E03FADEB711}" = Catalyst Control Center Localization Norwegian
"{117FBA8C-9325-4BCD-B19A-0BF21EA9A374}" = Catalyst Control Center Localization Spanish
"{122321B4-A450-0052-CAD8-B419C0EAD392}" = CCC Help Spanish
"{1606E90F-5327-EE07-9137-C518BF3DFFCE}" = Catalyst Control Center Localization Swedish
"{196BC239-53AB-615F-9B0D-FD2D61D31A58}" = Catalyst Control Center Localization Czech
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2D06A54D-6FA7-62F1-E824-E0109C069D8E}" = CCC Help Russian
"{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
"{2EBC713F-3022-A21B-6266-376ED7C43C07}" = CCC Help French
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}" = ATK Hotkey
"{3969961F-4B9A-DEB9-BC69-F0348E527DEA}" = Catalyst Control Center Localization Chinese Standard
"{39EAC702-D866-AA54-97C6-13E8AAAC2219}" = CCC Help Hungarian
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3CE73C5D-D8F0-D6D0-E5AB-39A798BF4571}" = Skins
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}" = ATI Catalyst Install Manager
"{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer
"{463F67F4-58D0-4C0D-BBC9-D0CC4E56D1B8}" = Windows Live UX Platform Language Pack
"{46663439-F39E-BF21-673C-19A035F9C708}" = Catalyst Control Center Localization Thai
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B0E4821-4852-41A5-BCD7-F7399C2C0D5F}" = Credos 1.0.13
"{4C4A9592-2854-E201-F7A9-2AE77AB35E37}" = CCC Help Portuguese
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4F2CE68F-EDBB-4592-BF07-5AC930A51029}" = Nero 7 Essentials
"{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A74F5DD-CD86-FE24-C8D3-9850F43FD42D}" = CCC Help Czech
"{5BD877FE-9E11-D996-DEDB-ABAF4A251C39}" = CCC Help Chinese Standard
"{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}" = ATKOSD2
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{6153EBDC-A52B-6B24-4A3C-5CC8F85BE0DF}" = Catalyst Control Center Graphics Full New
"{6173A4FC-D42D-69A6-52CA-A30496389760}" = ccc-core-static
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}" = NB Probe
"{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker
"{661EA4BC-FF51-FE25-7E59-D8BA41170189}" = Catalyst Control Center Localization Chinese Traditional
"{67645155-2149-7ED9-003E-92BFB7EA262A}" = Catalyst Control Center Localization Portuguese
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68AB9F5B-85BA-1A49-F5B9-103C172A90F6}" = Catalyst Control Center Localization Korean
"{68F423B1-B08A-4EFC-8414-408455443322}" = Tarzan
"{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{740323AF-4EFD-EB99-8632-6B5AA9D53411}" = Catalyst Control Center Localization Dutch
"{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}" = ICQ7.5
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common
"{7D5F5F2C-B978-2AD9-B54D-BC9006C35333}" = CCC Help Japanese
"{7D6E6E66-8B3D-42C2-DE13-E3F0C6A178D9}" = CCC Help Korean
"{7DFBD5A5-F88B-ED78-E5FD-FB994138BB25}" = ccc-utility
"{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
"{893EFD7C-B705-892C-E6E0-49BFB6C621BC}" = Catalyst Control Center Localization Russian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A30D5C0-BD4A-4E65-AADF-20A457DE6D38}" = Windows Live Family Safety
"{8B8FC6A3-3467-5786-657E-6893DDA7F52D}" = CCC Help Swedish
"{8CFEBE9C-F29F-4C49-80E0-7106970F8734}" = Power4Gear eXtreme
"{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}" = Camera RAW Plug-In for EPSON Creativity Suite
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Centrum zařízení Windows Mobile
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A70075D-6071-4704-EAF6-6DEB51CB777B}" = Catalyst Control Center Localization Finnish
"{9D513AEB-187D-C020-317A-5804F781CC95}" = CCC Help Chinese Traditional
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9D6D7811-43B3-463C-BC79-5D1755269989}" = Net4Switch
"{9D88CAFF-7CB3-916A-0A1F-5E0DB4ECD073}" = Catalyst Control Center Localization Danish
"{9EE7095B-F74E-4DC9-FAF7-75C940A1C3E9}" = Catalyst Control Center Localization French
"{A315B77A-24C5-95D9-9325-61C98FBB7C53}" = Catalyst Control Center Localization German
"{A3F7DB93-9DE6-416B-BB12-AF5F860209F3}_is1" = Glory of the Roman Empire
"{A480B428-5A5E-8D8F-6D8E-2CCBFF6029FA}" = CCC Help Norwegian
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7AF2BC7-FCFB-03CB-DA36-5E9D44A53091}" = CCC Help Turkish
"{A8FD0C55-0D21-89F3-57E9-1E22235765B3}" = CCC Help Finnish
"{A93622C0-6E86-11D8-AB2D-0050FC222B33}" = Reax 2004
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources
"{AC76BA86-7AD7-1029-7B44-A94000000001}" = Adobe Reader 9.4.5 - Czech
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B5DCE5D7-6FDD-D5C2-C6B7-14E264E695C9}" = Catalyst Control Center Core Implementation
"{B5FE6702-0B5F-6866-7FD2-A7B28BCAB15B}" = Catalyst Control Center Localization Japanese
"{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}" = EPSON Easy Photo Print
"{B89BD504-63FF-03DC-5B8B-CEBCEBF2B08D}" = CCC Help English
"{C0FC1C14-4824-4A73-87A6-9E888C9C3102}" = ASUS Splendid Video Enhancement Technology
"{C263E891-CA9F-7CE4-B31D-6A100D5D2F3C}" = CCC Help Polish
"{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail
"{C4693D41-87C5-A2E0-00AB-5E0A0A205E9E}" = CCC Help Italian
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DA4A7657-605C-4367-AF27-76C72DE4648C}" = ESET NOD32 Antivirus
"{DCC7315A-F551-0778-AFC1-C19D853E0AFA}" = Catalyst Control Center Localization Turkish
"{DCE907E3-4D72-4CD3-A08A-BEFC8C7A5869}" = Branding
"{DD73CA82-EA82-38AA-863D-9A24A018DC96}" = Microsoft .NET Framework 3.5 Language Pack SP1 - csy
"{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash
"{DF6D07CB-BA1B-60D3-8D51-69A5775AC7D9}" = CCC Help Thai
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E26DD81D-91CF-7348-65E2-5AC16E14612B}" = Catalyst Control Center Localization Polish
"{E33E9943-2679-C829-5E9E-4D981A1C264C}" = CCC Help Danish
"{E570CB6B-1CBC-4ADD-969F-7B3338A6BDB6}" = Windows Live Sync
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E7044E25-3038-4A76-9064-344AC038043E}" = Aktualizace ovladače pro aplikaci Centrum zařízení Windows Mobile
"{E7F0262E-84B8-9EBE-D6FD-E3865FCDB0EB}" = Catalyst Control Center Localization Italian
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED8C5498-6C39-92E6-B17F-414BF1722E42}" = Catalyst Control Center Graphics Previews Vista
"{EE5BC0BB-9EDA-423C-8276-48857B735D68}" = Prince of Persia Warrior Within
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F173C327-FAA5-D463-2CBD-A4818C7EDC8C}" = Catalyst Control Center Graphics Full Existing
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F49109F4-EA87-B982-8A66-CCD32C6FC8AF}" = CCC Help Greek
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F5AB638D-91F6-6517-9872-BE6996E06AF6}" = CCC Help Dutch
"{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie
"{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Armored Fist 3" = Armored Fist 3
"ATI Uninstaller" = ATI Uninstaller
"Blue Byte Game Channel" = Blue Byte Game Channel
"Call of Duty" = Call of Duty
"com.lightmaker.deagostini.ScrapBook.29F1EDFB1A6EC94F998B5392F8031DD941FC022D.1" = Hannah Montana Tajný Deník
"com.lightmaker.deagostini.ScrapBook.D45F7F2B1F9C3FBA2126914CB42B3E19064D325F.1" = Hannah Montana Tajný Deník
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"CX4300_5500_DX4400 Manuál" = CX4300_5500_DX4400 Manuál
"EPSON Printer and Utilities" = Software tiskárny EPSON
"EPSON Scanner" = EPSON Scan
"GOM Player" = GOM Player
"GPS Tuner" = GPS Tuner (remove only)
"ICQToolbar" = ICQ Toolbar
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD Ultra
"Jazz Jackrabbit 2 Christmas Chronicles 99" = Jazz Jackrabbit 2 Christmas Chronicles 99
"Microsoft .NET Framework 3.5 Language Pack SP1 - csy" = Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile CSY Language Pack" = Microsoft .NET Framework 4 Client Profile CSY Language Pack
"Mozilla Firefox (3.6.20)" = Mozilla Firefox (3.6.20)
"NEM3000" = NEM3000
"NemExpress" = NemExpress
"NemExpress CS" = NemExpress CS
"NemExpress RB" = NemExpress RB
"NOD32 v3.x FiX 1.1 by TemDono_is1" = NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)
"PC Suite For Android Handset" = PC Suite For Android Handset
"Pozemky_is1" = Pozemky 6.1.8
"Pozm" = Ceny pozemků
"Return to Castle Wolfenstein" = Return to Castle Wolfenstein
"S4Uninst" = The Settlers IV
"Skutečná Válka" = Skutečná Válka
"Skype™ for Pocket PC_is1" = Skype™ for Pocket PC 2.2
"SMSERIAL" = Motorola SM56 Data Fax Modem
"Spb Sudoku" = Spb Sudoku
"Spb Time" = Spb Time
"Spb Weather" = Spb Weather
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"T-Mobile Communication Centre" = Web'n'walk Manager
"Totalcmd" = Total Commander (Remove or Repair)
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR
"World of Warcraft" = World of Warcraft
"Zoo Empire_is1" = Zoo Empire 1.21
"Zoo Tycoon 2" = Zoo Tycoon 2

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Game Organizer" = EasyBits GO

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 18.8.2010 6:56:14 | Computer Name = MilanPC-prace | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 18.8.2010 6:58:23 | Computer Name = MilanPC-prace | Source = Application Error | ID = 1000
Description = Chybující aplikace NMIndexStoreSvr.exe, verze 2.0.5.0, časové razítko
0x45f51df1, chybující modul NMIndexStoreSvr.exe, verze 2.0.5.0, časové razítko
0x45f51df1, kód výjimky 0xc0000005, posun chyby 0x0001fbda, ID procesu 0x584, čas
spuštění aplikace 0x01cb3ec43d576eb4.

Error - 18.8.2010 11:27:07 | Computer Name = MilanPC-prace | Source = Application Error | ID = 1000
Description = Chybující aplikace zt.exe, verze 20.10.0.26, časové razítko 0x416471c8,
chybující modul binkw32.dll, verze 1.6.3.0, časové razítko 0x40dc8996, kód výjimky
0x80000001, posun chyby 0x0001bd1c, ID procesu 0xe38, čas spuštění aplikace 0x01cb3ee9c7d8081c.

Error - 18.8.2010 11:28:01 | Computer Name = MilanPC-prace | Source = Application Error | ID = 1000
Description = Chybující aplikace zt.exe, verze 20.10.0.26, časové razítko 0x416471c8,
chybující modul binkw32.dll, verze 1.6.3.0, časové razítko 0x40dc8996, kód výjimky
0xc0000005, posun chyby 0x0001bd1c, ID procesu 0x554, čas spuštění aplikace 0x01cb3ee9eb74b41e.

Error - 18.8.2010 11:28:24 | Computer Name = MilanPC-prace | Source = Application Error | ID = 1000
Description = Chybující aplikace zt.exe, verze 20.10.0.26, časové razítko 0x416471c8,
chybující modul binkw32.dll, verze 1.6.3.0, časové razítko 0x40dc8996, kód výjimky
0x80000001, posun chyby 0x0001bd1c, ID procesu 0x152c, čas spuštění aplikace 0x01cb3ee9f92ab144.

Error - 18.8.2010 15:34:31 | Computer Name = MilanPC-prace | Source = EventSystem | ID = 4621
Description =

Error - 19.8.2010 12:34:23 | Computer Name = MilanPC-prace | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 19.8.2010 12:34:34 | Computer Name = MilanPC-prace | Source = Application Error | ID = 1000
Description = Chybující aplikace NMIndexStoreSvr.exe, verze 2.0.5.0, časové razítko
0x45f51df1, chybující modul NMIndexStoreSvr.exe, verze 2.0.5.0, časové razítko
0x45f51df1, kód výjimky 0xc0000005, posun chyby 0x0001fbda, ID procesu 0x790, čas
spuštění aplikace 0x01cb3fbc659757e2.

Error - 20.8.2010 6:48:55 | Computer Name = MilanPC-prace | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 20.8.2010 6:49:00 | Computer Name = MilanPC-prace | Source = Application Error | ID = 1000
Description = Chybující aplikace NMIndexStoreSvr.exe, verze 2.0.5.0, časové razítko
0x45f51df1, chybující modul NMIndexStoreSvr.exe, verze 2.0.5.0, časové razítko
0x45f51df1, kód výjimky 0xc0000005, posun chyby 0x0001fbda, ID procesu 0xb98, čas
spuštění aplikace 0x01cb405548324b6e.

[ System Events ]
Error - 22.8.2011 12:51:57 | Computer Name = MilanPC-prace | Source = Service Control Manager | ID = 7000
Description =

Error - 22.8.2011 13:17:26 | Computer Name = MilanPC-prace | Source = disk | ID = 262151
Description = Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error - 22.8.2011 13:17:30 | Computer Name = MilanPC-prace | Source = disk | ID = 262151
Description = Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error - 22.8.2011 13:17:34 | Computer Name = MilanPC-prace | Source = disk | ID = 262151
Description = Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error - 22.8.2011 13:17:39 | Computer Name = MilanPC-prace | Source = disk | ID = 262151
Description = Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error - 22.8.2011 13:17:43 | Computer Name = MilanPC-prace | Source = disk | ID = 262151
Description = Zařízení \Device\Harddisk0\DR0 má chybný blok.

Error - 22.8.2011 14:03:24 | Computer Name = MilanPC-prace | Source = Service Control Manager | ID = 7034
Description =

Error - 22.8.2011 14:03:24 | Computer Name = MilanPC-prace | Source = Service Control Manager | ID = 7034
Description =

Error - 22.8.2011 14:03:24 | Computer Name = MilanPC-prace | Source = Service Control Manager | ID = 7034
Description =

Error - 22.8.2011 14:03:24 | Computer Name = MilanPC-prace | Source = Service Control Manager | ID = 7034
Description =


< End of report >

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, restartování NTB

#9 Příspěvek od vyosek »

:arrow: NOD je samozrejme cracknuty :twisted:

:arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    SRV - File not found [Unknown | Stopped] -- -- (wxpdrivers)
    SRV - File not found [Unknown | Stopped] -- -- (srvsysdriver32)
    SRV - File not found [Unknown | Stopped] -- -- (srviecheck)
    SRV - File not found [Unknown | Stopped] -- -- (srvbtcclient)
    SRV - File not found [Auto | Stopped] -- -- (ekrn)
    SRV - File not found [On_Demand | Stopped] -- -- (EhttpSrv)
    SRV - File not found [Auto | Stopped] -- -- (CLTNetCnService)
    SRV - [2011.05.29 12:01:37 | 000,073,600 | ---- | M] () [Auto | Running] -- C:\Windows\System32\ezGOSvc.dll -- (ezGOSvc)
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
    IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
    IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/skinit/icq/
    IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
    IE - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\URLSearchHook: {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - File not found
    FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q="
    FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q="
    FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "ICQ Search"
    FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "ICQ Search"
    FF - prefs.js..browser.startup.homepage: "resource:/browserconfig.properties"
    FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&q="
    [2011.05.18 19:38:41 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
    [2009.12.27 21:28:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
    [2008.12.31 00:18:19 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
    [2011.08.21 17:47:08 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-1.xml
    [2009.04.29 14:51:47 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-10.xml
    [2009.06.20 14:14:38 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-11.xml
    [2009.07.25 15:19:19 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-12.xml
    [2009.09.17 17:59:49 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-13.xml
    [2009.10.14 20:52:40 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-14.xml
    [2009.11.17 20:18:33 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-15.xml
    [2009.12.27 23:03:31 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-16.xml
    [2010.01.27 20:28:14 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-17.xml
    [2010.02.20 16:37:13 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-18.xml
    [2010.04.11 12:19:14 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-19.xml
    [2008.07.10 15:19:57 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-2.xml
    [2011.07.25 19:34:36 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-20.xml
    [2011.07.25 20:10:02 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-21.xml
    [2007.07.31 00:12:43 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-3.xml
    [2008.10.14 22:03:21 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-4.xml
    [2008.12.08 11:11:15 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-5.xml
    [2008.12.18 18:24:34 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-6.xml
    [2007.07.31 00:33:05 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-7.xml
    [2009.04.20 13:27:09 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-8.xml
    [2009.04.23 21:46:07 | 000,000,950 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-9.xml
    [2011.05.18 19:38:41 | 000,000,168 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.gif
    [2011.05.18 19:38:41 | 000,000,618 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.src
    [2011.03.30 15:14:34 | 000,001,042 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.xml
    [2009.06.30 19:54:00 | 000,001,632 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\live-search.xml
    [2008.12.31 00:18:09 | 000,003,915 | ---- | M] () -- C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\sweetim.xml
    [2009.07.18 18:55:17 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
    O2 - BHO: (XTTBPos00 Class) - {055FD26D-3A88-4e15-963D-DC8493744B1D} - Reg Error: Value error. File not found
    O2 - BHO: (Ask Search Assistant BHO) - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
    O3 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
    O3 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
    O4 - HKLM..\Run: [egui] File not found
    O4 - HKLM..\Run: [tray_ico] File not found
    O4 - HKLM..\Run: [tray_ico2] File not found
    O4 - HKLM..\Run: [tray_ico3] File not found
    O4 - HKLM..\Run: [tray_ico4] File not found
    O4 - HKU\S-1-5-21-1447561291-2587095337-3899909274-1000..\Run: [] File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
    O13 - gopher Prefix: missing
    O31 - SafeBoot: AlternateShell - services32.exe
    O33 - MountPoints2\{38122e00-b829-11e0-80b5-001bfcf4333c}\Shell - "" = AutoRun
    NetSvcs: ezGOSvc - C:\Windows\System32\ezGOSvc.dll ()
    [2011.08.22 17:56:34 | 000,000,000 | -H-D | C] -- C:\Windows\update.7.1
    [2011.08.22 17:56:23 | 000,000,000 | -H-D | C] -- C:\Windows\update.2
    [2011.08.22 17:13:36 | 000,000,000 | ---D | C] -- C:\Windows\ufa
    [2011.08.22 17:13:36 | 000,000,000 | ---D | C] -- C:\Windows\rpcminer
    [2011.08.22 17:13:36 | 000,000,000 | ---D | C] -- C:\Windows\phoenix
    [2011.08.22 16:49:16 | 000,000,000 | -H-D | C] -- C:\Windows\update.5.0
    [2011.08.21 20:26:27 | 000,000,000 | ---D | C] -- C:\Windows\av_ico
    [2011.08.21 20:24:34 | 000,000,000 | -H-D | C] -- C:\Windows\update.1
    [2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-2-0-lnk
    [2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-2-0
    [2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-15-0-lnk
    [2011.08.21 20:24:28 | 000,000,000 | -H-D | C] -- C:\Windows\update.tray-15-0
    [1 C:\Users\Milan\Desktop\*.tmp files -> C:\Users\Milan\Desktop\*.tmp -> ]
    [2011.08.22 18:18:28 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
    [2011.08.22 17:56:36 | 000,904,792 | ---- | M] () -- C:\Windows\geoiplist.rar
    [2011.08.22 17:56:36 | 000,246,272 | ---- | M] () -- C:\Windows\unrar.exe
    [2011.08.22 17:43:49 | 000,000,270 | RHS- | M] () -- C:\ProgramData\ntuser.pol
    [2011.08.22 17:13:35 | 005,589,370 | ---- | M] () -- C:\Windows\phoenix.rar
    [2011.08.22 17:13:35 | 000,182,617 | ---- | M] () -- C:\Windows\ufa.rar
    [2011.08.22 17:13:34 | 001,075,284 | ---- | M] () -- C:\Windows\rpcminer.rar
    [2011.08.22 16:49:07 | 000,000,000 | ---- | M] () -- C:\Windows\loader2.exe_ok
    [2011.08.22 16:48:52 | 000,137,728 | ---- | M] () -- C:\Windows\systemup.exe
    [2011.08.22 16:42:55 | 000,258,048 | ---- | M] () -- C:\Windows\sysdriver32_.exe
    [2011.08.22 16:42:55 | 000,258,048 | ---- | M] () -- C:\Windows\sysdriver32.exe
    [2011.08.21 20:11:06 | 001,213,440 | ---- | M] () -- C:\Windows\services32.exe
    [2008.05.17 13:10:08 | 000,000,000 | ---D | M] -- C:\Users\Milan\AppData\Roaming\ICQ Toolbar
    
    :reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    ""=-
    "AlcoholAutomount"=-
    "ICQ"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"=-
    "SunJavaUpdateSched"=-
    
    :files
    C:\Program Files\ICQ6Toolbar
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

Re: FB vir, restartování NTB

#10 Příspěvek od LukassM »

All processes killed
========== OTL ==========
Service wxpdrivers stopped successfully!
Service wxpdrivers deleted successfully!
Service srvsysdriver32 stopped successfully!
Service srvsysdriver32 deleted successfully!
Service srviecheck stopped successfully!
Service srviecheck deleted successfully!
Service srvbtcclient stopped successfully!
Service srvbtcclient deleted successfully!
Service ekrn stopped successfully!
Service ekrn deleted successfully!
Service EhttpSrv stopped successfully!
Service EhttpSrv deleted successfully!
Service CLTNetCnService stopped successfully!
Service CLTNetCnService deleted successfully!
Error: Unable to stop service ezGOSvc!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ezGOSvc deleted successfully.
C:\Windows\System32\ezGOSvc.dll moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-21-1447561291-2587095337-3899909274-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\StartPageCache| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
C:\Program Files\ICQ6Toolbar\ICQToolBar.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9CB65206-89C4-402c-BA80-02D8C59F9B1D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CB65206-89C4-402c-BA80-02D8C59F9B1D}\ deleted successfully.
Prefs.js: "ICQ Search" removed from browser.search.defaultenginename
Prefs.js: "http://search.live.com/results.aspx?FORM=IEFM1&q=" removed from browser.search.defaulturl
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
Prefs.js: "http://search.icq.com/search/afe_result ... r=1.1.9&q=" removed from keyword.URL
Prefs.js: "ICQ Search" removed from sweetim.toolbar.previous.browser.search.defaultenginename
Prefs.js: "ICQ Search" removed from sweetim.toolbar.previous.browser.search.selectedEngine
Prefs.js: "resource:/browserconfig.properties" removed from browser.startup.homepage
Prefs.js: "http://search.icq.com/search/afe_result ... id=afex&q=" removed from sweetim.toolbar.previous.keyword.URL
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\META-INF folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\components folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} folder moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-1.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-10.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-11.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-12.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-13.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-14.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-15.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-16.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-17.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-18.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-19.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-2.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-20.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-21.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-3.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-4.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-5.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-6.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-7.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-8.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin-9.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.gif moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.src moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\icqplugin.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\live-search.xml moved successfully.
C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\searchplugins\sweetim.xml moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{055FD26D-3A88-4e15-963D-DC8493744B1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
File C:\Program Files\ICQ6Toolbar\ICQToolBar.dll not found.
Registry value HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found.
File C:\Program Files\ICQ6Toolbar\ICQToolBar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\egui deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico2 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico3 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tray_ico4 deleted successfully.
Registry value HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableSecureUIAPaths deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\\AlternateShell deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{38122e00-b829-11e0-80b5-001bfcf4333c}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{38122e00-b829-11e0-80b5-001bfcf4333c}\ not found.
ezGOSvc removed from NetSvcs value successfully!
File C:\Windows\System32\ezGOSvc.dll not found.
C:\Windows\update.7.1 folder moved successfully.
C:\Windows\update.2 folder moved successfully.
C:\Windows\ufa folder moved successfully.
C:\Windows\rpcminer folder moved successfully.
C:\Windows\phoenix\kernels\poclbm folder moved successfully.
C:\Windows\phoenix\kernels\phatk folder moved successfully.
C:\Windows\phoenix\kernels folder moved successfully.
C:\Windows\phoenix folder moved successfully.
C:\Windows\update.5.0 folder moved successfully.
C:\Windows\av_ico folder moved successfully.
C:\Windows\update.1 folder moved successfully.
C:\Windows\update.tray-2-0-lnk folder moved successfully.
C:\Windows\update.tray-2-0 folder moved successfully.
C:\Windows\update.tray-15-0-lnk folder moved successfully.
C:\Windows\update.tray-15-0 folder moved successfully.
C:\Users\Milan\Desktop\~WRL3059.tmp deleted successfully.
C:\Windows\l1rezerv.exe moved successfully.
C:\Windows\geoiplist.rar moved successfully.
C:\Windows\unrar.exe moved successfully.
C:\ProgramData\ntuser.pol moved successfully.
C:\Windows\phoenix.rar moved successfully.
C:\Windows\ufa.rar moved successfully.
C:\Windows\rpcminer.rar moved successfully.
C:\Windows\loader2.exe_ok moved successfully.
C:\Windows\systemup.exe moved successfully.
C:\Windows\sysdriver32_.exe moved successfully.
C:\Windows\sysdriver32.exe moved successfully.
C:\Windows\services32.exe moved successfully.
C:\Users\Milan\AppData\Roaming\ICQ Toolbar folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AlcoholAutomount deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ICQ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
========== FILES ==========
C:\Program Files\ICQ6Toolbar folder moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes

User: Default User

User: Milan
->Temp folder emptied: 91664025 bytes
->Temporary Internet Files folder emptied: 76263442 bytes
->Java cache emptied: 517835 bytes
->FireFox cache emptied: 123488468 bytes
->Flash cache emptied: 3336517 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 458465528 bytes
RecycleBin emptied: 4054199600 bytes

Total Files Cleaned = 4 585,00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User

User: Milan
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.26.5 log created on 08222011_214816

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, restartování NTB

#11 Příspěvek od vyosek »

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

Re: FB vir, restartování NTB

#12 Příspěvek od LukassM »

ComboFix 11-08-22.04 - Milan 22.08.2011 22:18:36.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.1919.1108 [GMT 2:00]
Spuštěný z: c:\users\Milan\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\IsUn0405.exe
c:\windows\iun6002.exe
c:\windows\proc_list1.log
c:\windows\security\Database\tmp.edb
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
c:\windows\system32\userinit.exe . . . je infikován!!
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-22 do 2011-08-22 )))))))))))))))))))))))))))))))
.
.
2011-08-22 19:48 . 2011-08-22 19:48 -------- d-----w- C:\_OTL
2011-08-22 17:36 . 2011-08-22 17:36 -------- d-----w- c:\program files\trend micro
2011-08-22 17:36 . 2011-08-22 17:36 -------- d-----w- C:\rsit
2011-08-19 12:28 . 2011-05-29 10:01 718208 ----a-w- c:\windows\system32\ezGOSvcApp.exe
2011-08-19 12:24 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D417A0FA-C57D-461A-A47A-C780585101D1}\mpengine.dll
2011-08-10 14:32 . 2011-06-17 16:03 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-08-10 14:31 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 14:31 . 2011-06-06 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-10 14:31 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-10 14:31 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-10 14:31 . 2011-06-17 20:13 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-02 20:12 . 2011-08-02 20:12 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-27 17:18 . 2011-07-27 17:18 -------- d-----w- c:\program files\PC Suite For Android Handset
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-22 20:32 . 2008-02-07 17:11 45056 ----a-w- c:\windows\system32\acovcnt.exe
2011-07-11 15:14 . 2011-07-11 15:14 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-02 13:34 . 2011-07-13 13:50 2043392 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"T-Mobile Communication Centre"="c:\program files\T-Mobile\Web'n'walk Manager\Manager.exe" [2007-10-25 956296]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 815104]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2006-12-5 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2005-05-26 16:12 544768 ----a-w- c:\windows\sm56hlpr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-05-17 436792]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
S2 lxbk_device;lxbk_device;c:\windows\system32\lxbkcoms.exe [2008-02-19 537256]
S3 WCPU;WCPU;c:\program files\P4G\WCPU.sys [2007-01-02 11120]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
uStart Page =
mStart Page =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{7608D99D-0DD1-4A8B-A49A-19BE351CCBA8}: NameServer = 194.228.2.1,194.228.41.113
FF - ProfilePath - c:\users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/skinit/icq/
FF - Ext: Arabic spell-checking dictionary: ar@dictionaries.addons.mozilla.org - %profile%\extensions\ar@dictionaries.addons.mozilla.org
FF - Ext: České slovníky pro kontrolu pravopisu: cs@dictionaries.addons.mozilla.org - %profile%\extensions\cs@dictionaries.addons.mozilla.org
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM_ActiveSetup-ccc-core-static - msiexec
AddRemove-Call of Duty - d:\progra~1\CALLOF~1\Uninstall\Unwise.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
AddRemove-NOD32 v3.x FiX 1.1 by TemDono_is1 - c:\program files\ESET\ESET NOD32 Antivirus\unins000.exe
AddRemove-Pozm - d:\acons10\Pozemky6\Unst.exe
AddRemove-Return to Castle Wolfenstein - d:\hry\RETURN~1\Uninstall\Unwise.exe
AddRemove-S4Uninst - c:\windows\IsUn0405.exe
AddRemove-Zoo Empire_is1 - d:\zoo empire\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-22 22:34
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*8*W* %\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Hß*Z%]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Hß*Z%\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]%)*Ë*]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]%)*Ë*\OpenWithList]
@Class="Shell"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000002e
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files\ATK Hotkey\Hcontrol.exe
c:\program files\ATKOSD2\ATKOSD2.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\BingBar\SeaPort.EXE
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\windows\system32\DllHost.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2011-08-22 22:44:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-22 20:43
.
Před spuštěním: 6 975 422 464
Po spuštění: 6 676 672 512
.
- - End Of File - - D2722DCEDD2BC7C01FA044FF59CE3B89

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, restartování NTB

#13 Příspěvek od vyosek »

:arrow: Stahnete SytemLook (viz muj podpis) a ulozte jej na plochu
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    :filefind
    userinit.exe
  • Kliknete na Look
  • Tlacitko Look se zmeni na Scanning a zsedne
  • Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
  • Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
:arrow: Mate instalacni dvd od windows :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

LukassM
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 22 srp 2011 17:32

Re: FB vir, restartování NTB

#14 Příspěvek od LukassM »

SystemLook 30.07.11 by jpshortstuff
Log created at 23:15 on 22/08/2011 by Milan
Administrator - Elevation successful

========== filefind ==========

Searching for "userinit.exe"
C:\Windows\ERDNT\cache\userinit.exe --a---- 25088 bytes [20:40 22/08/2011] [07:33 19/01/2008] 0E135526E9785D085BCD9AEDE6FBCBF9
C:\Windows\System32\userinit.exe --a---- 25088 bytes [13:22 10/08/2008] [07:33 19/01/2008] 0E135526E9785D085BCD9AEDE6FBCBF9
C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe --a---- 24576 bytes [08:43 02/11/2006] [09:45 02/11/2006] 22027835939F86C3E47AD8E3FBDE3D11
C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe --a---- 25088 bytes [13:22 10/08/2008] [07:33 19/01/2008] 0E135526E9785D085BCD9AEDE6FBCBF9

-= EOF =-


:arrow: systém byl nejspíš na NTB již při koupi a jestli bylo instalační (opravné) dvd přibaleno netuším.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, restartování NTB

#15 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Restore::
    c:\windows\system32\userinit.exe
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000000
    "DisableThumbnailCache"=dword:00000000
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000000
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "AntiVirusOverride"=dword:00000000
    
    DDS::
    uStart Page =
    mStart Page = 
    
    Firefox::
    FF - ProfilePath - c:\users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\ls7kk8co.default\
    FF - prefs.js: browser.search.defaulturl -
    FF - prefs.js: browser.search.selectedEngine -
    FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/skinit/icq/
    
    RegLock::
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*8*W* %\OpenWithList]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Hß*Z%]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Hß*Z%\OpenWithList]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]%)*Ë*]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]%)*Ë*\OpenWithList]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*8*W* %\OpenWithList]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Hß*Z%]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Hß*Z%\OpenWithList]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]%)*Ë*]
    [HKEY_USERS\S-1-5-21-1447561291-2587095337-3899909274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]%)*Ë*\OpenWithList]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět